SecOps ForcesContinuous Microsoft 365 posture

Managed services

Your configurationdrifts continuously.You are notified.

An admin adds a rule, a project opens a share, a contractor gets access. None of it is malicious, and yet your security level drops week after week. Continuous monitoring turns that invisible drift into a signal.

Subscription · Billed from 100 users per tenant · Exportable evidence

posture.m365 — monitoring activeDay 30
72/100 · after remediation
Drift detected this month2 changes
Admin accounts without MFAnone left
External sharingexpires in 30 d
Legacy authenticationblocked
Evidence exportsup to date

The problem

An audit protects you
on the day it is run.

What degrades between two audits shows up nowhere. Here is what continuous monitoring catches, and what a point-in-time check misses by design.

Drift

An exception that becomes permanent

Access opened "just for the project" is still active two years after the project ended, and nobody remembers it.

Evidence

An insurer questionnaire due tomorrow

With no dated history, answering takes a week of manual collection — and the answer stays declarative.

Compliance

NIS2 requires continuity, not a snapshot

The directive requires ongoing risk management. An annual report does not demonstrate a continuous process.

Regression

A fix undone without anyone noticing

A control applied in March can be reverted in June by an unrelated change. Nobody sees it.

Tenant at initial audit — 355 controls run

174failing
134passing
47not applicable
MCBP 5.032 %
CISA15 %
EIDSCA32 %
ORCA85 %

Interface preview — illustrative data.

What the platform does

One scan, six frameworks, remediation included.

No agent to deploy, no connector to maintain. You connect the tenant; the platform runs the controls and returns an assessment your own teams can act on directly.

Several tenants, one view

A consolidated score across all your tenants, and the detail of each one click away. Built for multi-entity groups as much as for providers managing several customers — every control carries the name of the tenant it belongs to.

More than 300 controls per tenant, six frameworks

MCBP 5.0, CISA, EIDSCA, MAESTER, ORCA — and your own, grouped under CUSTOM. Each framework has its own score and its count of controls passed, failed or skipped. You see where you stand framework by framework, not just on average.

Baselines ready to use, or your own

The controls that matter for an E3 or E5 licence, at level 1 or 2, are already grouped. You can also build your own by picking controls one by one — by framework, category, service or licence — and apply it across the estate.

Fixes applied from the platform

Every control says whether it can be fixed automatically. When it can, the fix runs from the control’s own page, and the platform records what was run and when. It refuses to run on a control that already passes — you do not fix what is not broken.

Every control is documented

For each one: what it checks, why it is a risk, and — less common — the impact the fix will have on your users. Then how to do it, in the Microsoft interface and in PowerShell, with links to the original documentation and the reference benchmark. Your teams can fix it without us.

Assign, schedule, follow up

A failing control can be assigned to a team, a project or a person, with a status, a due date and notes. That is what turns a list of findings into a plan of work — and what lets you answer "where are we on this?" six weeks later without reopening the whole subject.

History, not just a snapshot

The score is tracked over time, scan after scan. That is what separates a posture that is improving from one that is quietly degrading — and what you show to prove an ongoing effort, where a dated screenshot proves nothing.

An assistant that knows your data

You ask it where to start, it answers on your own results: how many controls are failing, on which frameworks, in what order to take them and why. It helps you decide and understand a control; it does not decide for you.

What you can show

The numbers you will be asked for.

An insurer, a customer auditing you or your own board do not want to see your console. They expect dated figures and the means to verify them. Everything below exports.

Overall score

The compliance level across the estate, out of one hundred. The figure you quote to the board, and the one you compare from one quarter to the next.

Controls passed, failed, skipped

The detail behind the score, including the controls deliberately skipped — a documented non-applicable control is worth more than a failure nobody explains.

Score per framework

MCBP, CISA, EIDSCA, MAESTER, ORCA. When a customer imposes a specific framework, you answer on that one rather than on an average that means nothing to them.

Score history

The curve since the first scan. That is what demonstrates a continuous effort — what NIS2 expects, and what an insurer looks at before renewing.

Automatically fixable controls

How many of your failures need no project and no budget. Useful for arbitration: what is free gets done now, the rest gets planned.

Dated export, control by control

The full list, with the control identifier, the result, the tenant and the execution date. That is the exhibit you attach to a file, not a screenshot.

What you get

Evidence, not a stream of alerts.

The posture score

A single figure, comparable over time, that you can present to the board without explaining three frameworks.

Updated continuously

Exportable evidence

The timestamped history of gaps and fixes, exportable for your insurer, your auditor or your NIS2 file.

PDF & CSV

Pricing

Clear pricing,
per user.

A subscription to the platform, billed on the number of users in your tenant. On an annual commitment it comes to €1.20 per user per month — 20% less than monthly.

The platform

€1.20/ user / month · billed yearly

From 100 to 500 users per tenant. Beyond that, tapered pricing on request.

  • Continuous monitoring, six frameworks
  • Remediation from the platform, exportable evidence
  • Multi-tenant, baselines and a prioritization assistant
  • Data hosted in France, and yours to keep

The initial audit (€2,500) and guided remediation (on request) are added as options, when you decide.

Where to start

Rarely from zero.

Most customers begin with a full assessment, then place the corrected configuration under monitoring.

Microsoft 365 audit

The full picture before monitoring: 300+ controls, scanned in 30 to 60 minutes.

Optional · €2,500

Guided remediation

If you would rather have our experts apply the fixes alongside your teams than do it alone.

Optional · On request

Frequently asked

Before subscribing.

Is the price the same at any size?
From 100 to 500 users per tenant it is €1.50/user/month. Beyond that the grid tapers: a single rate stops making sense at a few thousand users, so we set it in thirty minutes once we understand your scope.
Why is it billed from 100 users?
There is no minimum size to qualify: the service works whatever your headcount. It is the billing that has a floor, set at 100 users per tenant — below that, onboarding costs more than the subscription is worth, and we would rather say so than sell you an oversized service. The floor applies to the Microsoft 365 scope only: email security is priced per domain.
Does this replace our SOC?
No. A SOC watches events and responds to incidents. We watch configuration so fewer incidents become possible. The two complement each other; we work upstream.
What exactly do you see of our data?
Your environment configuration, never the content of your messages or files. Data is hosted in France and remains yours.

Where does your posture stand today?

Thirty minutes to talk it through. If a one-off audit is enough in your situation, we will say so rather than sell you a subscription.